Burp Suite用户论坛

登录以发布

什么是正面或假阳性?还是您需要解决问题?Cookie操纵(基于DOM)

卢卡斯|上次更新:2021年11月4日01:00 UTC

我有一个问题,您想知道误报还是积极的?还是您需要修复?http/1.1 200 OK日期:MON,SEP 2021 14:03:31 GMT服务器:Apache strict-transport-security:max-age = 31536000;包括ububdomains x-power-by:servlet/3.1 x- oneagent-j infoction:true Cache-control:无缓存,无存储,必备的到期:THU,1970年1月1日00:00:00:00 GMT Content-Location-Location-Location-Location-Location-thu: /pnegocios2/wps/portal/portaldenegociosnovo/!ut/p/z1/04_Sj9CPykssy0xPLMnMz0vMAfIjo8zifdx9PA0sLYz8DJzdjAwCHcOCTdx9jQxNfE30wwkpiAJKG-AAjgZA_VGElBTkRhikOyoqAgBzNoDA/dz/d5/L2dBISEvZ0FBIS9nQSEh/ Pragma: no-cache Vary: Cookie,User-Agent,Accept-Encoding Server-Timing: dtRpid;desc=“ - 50114999”内容类型:text/html;charset = utf-8内容语言:en set-cookie:wsp9-pnegocios = rd5o000000000000000000000000000000000000000000fffffffffffff0acd3a5co80;到期= Mon,13-Sep-2021 23:23:31 GMT;路径=/pnegocios2/;httponly CACHE-CONTROL:无存储的高速缓存控制:No-Cache通过:1.1 wwwn.bradescoseguros.com.br(访问Gateway-ag-77b1b8c198108543-117622309)> <! - Google Tag Manager-> <... [SNIP] ...动态分析数据是从location.href读取并传递到document.cookie的。 The following value was injected into the source: ?redirect=i29j89u05n%27%22`'"/i29j89u05n/>coyxramjnt& The previous value reached the sink as: redirect=i29j89u05n%27%22`'"/i29j89u05n/>coyxramjnt;expires=Tue, 14 Sep 2021 15:20:14 GMT;path=/ The stack trace at the source was: at Object._0x16d0e7 [as proxiedGetterCallback] (:1:591983) at Object.get href [as href] (:1:299867) at getUrlParam (https://wwwn.bradescoseguros.com.br/pnegocios2/wps/contenthandler/!ut/p/digest!XUbyaP-QyHkijF1b_2hgww/dav/fs-type1/themes/BSPN-PortalNegocios-Tema/assets/js/components.min.js:2093:79) at includeUrlParamInCookies (https://wwwn.bradescoseguros.com.br/pnegocios2/wps/contenthandler/!ut/p/digest!XUbyaP-QyHkijF1b_2hgww/dav/fs-type1/themes/BSPN-PortalNegocios-Tema/assets/js/components.min.js:2115:22) at https://wwwn.bradescoseguros.com.br/pnegocios2/wps/contenthandler/!ut/p/digest!XUbyaP-QyHkijF1b_2hgww/dav/fs-type1/themes/BSPN-PortalNegocios-Tema/assets/js/components.min.js:2120:1 The stack trace at the sink was: at Object.Ghpje (:1:181523) at Object.EUwOT (:1:573898) at Object.HXkfI (:1:585603) at HTMLDocument.Object..set (:1:586874) at setCookie (https://wwwn.bradescoseguros.com.br/pnegocios2/wps/contenthandler/!ut/p/digest!XUbyaP-QyHkijF1b_2hgww/dav/fs-type1/themes/BSPN-PortalNegocios-Tema/assets/js/components.min.js:697:21) at includeUrlParamInCookies (https://wwwn.bradescoseguros.com.br/pnegocios2/wps/contenthandler/!ut/p/digest!XUbyaP-QyHkijF1b_2hgww/dav/fs-type1/themes/BSPN-PortalNegocios-Tema/assets/js/components.min.js:2117:9) at https://wwwn.bradescoseguros.com.br/pnegocios2/wps/contenthandler/!ut/p/digest!XUbyaP-QyHkijF1b_2hgww/dav/fs-type1/themes/BSPN-PortalNegocios-Tema/assets/js/components.min.js:2120:1

你需要登录发布答复。或者在这里注册, 免费。